Skip to main content
Jump to a category page

Central Texas MHMR, doing business as Center for Life Resources (“CFLR”), has notified clients that hackers accessed its internal network and copied files containing extensive personal, financial, and medical information. CFLR is a community mental health center based in Brownwood, Texas, providing mental health, substance use, autism, and intellectual/developmental disability services across Central Texas.

CFLR discovered unusual activity on its network on November 17, 2025, and determined that an unknown actor had accessed the network and copied files between November 14 and 15, 2025. CFLR then conducted what its notification letter describes as a “thorough and time-intensive review” to identify exactly whose information was involved. Individual notification letters are dated July 22, 2026, nearly eight months after the intrusion was discovered.

Eight Months Between Discovery and Notice

CFLR knew its network had been breached in mid-November 2025. The letters informing clients that their Social Security numbers, medical records, and other sensitive information may have been exposed didn’t go out until July 22, 2026, a gap of roughly eight months. For a community mental health provider whose clients include people with intellectual and developmental disabilities, that’s eight months during which affected individuals had no way to know they needed to watch their credit, freeze their files, or protect themselves from fraud.

What Information Was Exposed?

According to the Texas Attorney General filing, the compromised information includes:

  • Full Name
  • Address
  • Social Security Number
  • Driver’s License Number
  • Government-Issued ID Number
  • Financial Information
  • Medical Information
  • Health Insurance Information
  • Date of Birth

That’s nearly every category of sensitive personal and medical data at once, one of the most complete identity-theft “kits” a hacker could ask for.

How Many People Are Affected?

The Texas Attorney General’s filing (published 07/23/2026) confirms at least 10,031 Texas residents. Vermont’s Attorney General separately confirms 2 Vermont residents from the same incident, and Massachusetts has a corresponding notification filing on record. Given CFLR’s Central Texas client base, the Texas figure is likely close to the true total, but the multi-state filings show the exposure wasn’t limited to one state.

What Is CFLR Offering?

CFLR is offering 24 months of credit monitoring and identity protection services through TransUnion/Cyberscout, at no cost. Affected individuals must enroll within 90 days of the date of their letter (July 22, 2026) to activate the service.

Your Information Is at Risk

A Social Security number combined with a driver’s license number, financial information, and full medical and health insurance records gives identity thieves nearly everything they need, not just to open new credit in someone’s name, but to commit medical identity theft and insurance fraud as well. CFLR states it is not aware of any identity theft or fraud related to this incident as of the date of the letter, but that doesn’t mean affected individuals are in the clear.

Do You Have Legal Options?

Organizations that collect Social Security numbers and protected health information have a legal duty to safeguard that data and to notify affected individuals without unreasonable delay. An eight-month gap between discovering a breach and telling the people affected raises real questions about whether that duty was met.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

How many people were affected by the Center for Life Resources data breach?

At least 10,031 Texas residents, plus 2 Vermont residents and additional individuals covered by a Massachusetts filing. The true multi-state total may be higher.

What information was exposed?

Names, addresses, Social Security numbers, driver’s license numbers, government-issued ID numbers, financial information, medical information, health insurance information, and dates of birth.

Why did it take so long to be notified?

CFLR discovered the intrusion on November 17, 2025, but individual notification letters weren’t sent until July 22, 2026, about eight months later. CFLR states it spent that time identifying exactly which files and individuals were affected.

What should I do if I received a letter?

Enroll in the free 24-month credit monitoring offer within 90 days, place a fraud alert or credit freeze with Equifax, Experian, and TransUnion, monitor financial and medical statements closely, and consider speaking with a data breach attorney about your options.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now